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MEMORANDUM FOR: Deputy Director of Central Intelligence DD A Registry 


_ Gr : 
; Jo ‘ e 
FROM John F. Blak File 
Deputy Director for Administration 


SUBJECT : Privacy Act of 1974: Supplemental Guidance 
for Matching Programs 


REFERENCE : D/OMB memo to Heads of Executive Departments 
and Agencies dtd 2 Aug 78, same subject 


1. Action Requested: Your approval of the recommendation 
contained in paragraph 4 concerning supplemental guidance for matching 


programs. 


2. Background: During mid-1977 the Office of the Inspector 
General in the Department of Health, Education and Welfare began a 
program to reduce fraud and unauthorized payments in certain Federal 
assistance programs. A major part of this program, called "Project 
Match" involved a computerized comparison of files of recipients of 

aid to families with dependent children with lists of Federal employees 
maintained by the Civil Service Commission and the Department of Defense. 


The original "Project Match" was subject to the Privacy Act 
of 1974 because it was performed by a Federal agency using Federal 
personnel records. OMB agreed that disclosures of computer tapes of 
personnel files to HEW can be covered as a "routine use" as defined in 
the Privacy Act. However, as the matching programs present the potential 
for significant invasion of personal privacy, OMB undertook the develop- 
ment of guidelines to be used by agencies in future matching programs. 
HEW has not acquired additional records for matching programs other than 
Project Match. Two (2) more matching programs planned by HEW were 
suspended pending development and issuance of final guidelines by OMB. 
Referent memorandum provides supplemental guidance and requests our 
views/comments about them. 


& 


Action passed to Compt 10/20/78 
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3. Staff Position: At the September 1977 meeting of the 
Interagency Advisory Group, CSC, the officer-in-charge of Project Match 
operations, Mr. Paul Marion, Director of the HEW Audit Staff, discussed 
the program activities with the attending Federal personnel representa- 
tives. Mr. Marion acknowledged to the CIA representative that CIA, FBI, 
and other sensitive agencies could not provide employee rosters and 
stated that he did not expect or request that CIA participate. The 
Agency, therefore, did not take part in Project Match. (Note: Names 


' of Agency employees are included in the definition of Intelligence 


Sources and Methods as defined in Section 6 of the CIA Act of 1949, as 
amended.) 


4. Recommendation: I recommend that no written comments about 
the Supplemental Guidance be submitted. It is suggested, however, that 
the Office of the Comptroller contact the OMB Liaison Officer and 
indicate that we are not making comments because the Agency is not a 
participant in the matching programs. 


STATINTL 
John F. Blake 
The recommendation containe paragraph 4 is: 
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WASHINGTON, D.C. 20503 
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MEMORANDUM TO HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIE 


August 2, 1978 


Subject: Privacy Act of 1974: Supplemental Guidance for 
Matching Programs 


This memorandum requests the views of your agency on the 
- attached supplement to the OMB Guidelines on the Privacy 
Act of 1974. 


procedures for the conduct of “matching programs," which are 
computerized comparisons of personal records maintained by 
various agencies, for the purpose of curtailing fraud ox 
unauthorized payments under Federal programs, or to aid in 
collecting debts owed the Federal Government. A summary of 
the background of the guidelines, along with its full text, 


The supplemental guidelines have been developed to establish 3 | 
is attached. | 


Your views are requested by September 14, 1978, and should he 

submitted to the Information Systems Policy Division, Room | 

9002, New Executive Office Building, Washington, D.C. 20503.- 

Any questions may be directed to the Division at (202)395~4814. 
| 


Sincere], 


ne Mf Eh Toe 


James T. McIntyre, Jr. 
Director 


Attachment 
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OFFICE OF MANAGEMENT AND BUDGET - 


Privacy Act of 1974: Supplemental Guidance for 
- Matching Programs | 


Request for Comments » 


Sone ween et orien ea 


a re en 
re ier ae Showers 


AGENCY: Office of Management: and Budget... |” ee ae 
ACTION: Request for comments on proposed supplement +. 
to OMB Privacy Act Guidelines ~ Bi le ee tee ser 


ee 


SUMMARY : These guidelines establish procedures an@ limita - 
tions for matching programs carried 
to reduce fraud or unauthorized payments in a Federal 


tching. The .-.. 


Federal benefit programs. 


DATE: Comments must be rece 
14, 1978, ean oo. Yo, | Geet a 


ived on or before September 


ADDRESS: Written comments should be ‘addressed ta the 
Information Systems Policy Division, Office of Management 
and Budget, Room 9002, New Executive Office Building, -. 


Washington, D.C. 20503. 


FOR FURTHER INFORMATION CONTACT: Leslie Greenspan, gn 
Information Systems Policy Division, Room 9002, NEOB, .- | 
(202) 395-4914. Bele Nat peat glk 


as 


A major 
involved a 
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The proponents of Project Match asserted that it was 
necessary to preserve the integrity of Federal assistance ~ 
programs, to prevent or curtail fraud. and abuse, and that | 

it would result in considerable financial benefits to the 
Government. Critics of.the program questioned whether 

the matching was an invasion of privacy; whether the. 
benefits were great enough to outweigh either the privacy 
considerations or the cost of the matching itself; and te 
whether the due process rights of the subjects of the 
matching were being observed. The issue is complex, and 
interests on both sides are compelling. ..The guidelines --...+ 
attempt to balance the competing interests involved. ..- tn 
Project Match was subject to the Privacy Act of 1974 . : ee 
because it was performed by a Federal agency using Federal ty 
personal records. The Office of Management and Budget has yas. 
responsibility for assisting agencies iin interpreting so Le 
the Privacy Act. When asked for its views on the appro- sees 
priate basis for making disclosures of computer tapes 

of personnel files to HEW, OMB advised that a "routine one ae 
use" was the most appropriate mechanism. The Act defines -. 

a routine use as a disclosure, made without the advance - 
written consistent of the subject of the record, which is - 
compatible with the purpose for which ‘the record was -. Se 
collected (5 U.S.C. 552a(a)(7)). Before an agency can 
make a disclosure pursuant toa routine use, it must y 
publish in the Federal Register a notice describing it,. - 
and allow 30 days for public comment (5 U.S.C.: 552a(e) (11}}..- - 


a eee 


” 


While Project Match disclosures met the requirements for a. 
routine use under the Privacy Act and significant benefits - 
could be gained it is also clear that matching programs: — 
present the potential for significant invasions of PSE <3 ste 
sonal privacy. Because of its reponsibilities under the ° cee 
Privacy Act, and at the request of the interested agencies - 
and the relevant congressional committees, OMB in con- - 
junction with ‘the Domestic Policy Staff undertook the 
development of guidelines to be used by agencies in | 
future matching programs. During the period of the 
formulation of the guidelines, HEW has not acquired 
additional records for matching programs other than 
Project Match. Two additional matching programs 
planned by HEW were suspended pending development of 
these guidelines. The two programs are (1) a matching 
of the the Federal employment rolls with the list of 
defaulters under the Guaranteed Student Loan Program, | 
and (2) a comparison of the Federal employment rolls - : 
with the old age and.disability recipients under programs 
of Social Security Administration. OMB has advised 
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matching programs providing they are con- 
ducted in accordance with the proposed guidelines, but 
that no further matching programs should he conducted. 
until public comments on the proposed guidelines are 
evaluated and final guidelines are issued. 


The guidelines are advisory rather than mandatory, for 
two reasons. First, OMB's responsibility under the Act 
is to provide oversight and assistance, rather than to he 
a regulatory body, and second, the Privacy Act places 

the final responsibility for agency actions with the 
agencies themselves. It is OMB’s view that in Situations 
such as this, an agency can best decide whether to 
disclose a record, and that OMB should not mandate or 
prohibit disclosures of records, at least until more 


experience with matching programs is gained. OMB 
expects, however, that agencies will follow this guidance. 


During the comment period, OMB will continue to discuss 
with the Internal Revenue Service the interplay of these 
guidelines with existing similar requirements for the 
Internal Revenue Service. 


The text of the guidelines is set forth below. 


”~ 


c 
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OFFICE OF MANAGEMENT AND BUDGET ‘ 
Implementation of the Privacy Act of s74 
_ Supplementary Guidance 
The following sets forth guidelines on matching programs 
conducted by Federal agencies, and. further supplements the 


Office of Management and ‘Budget guidelines for. implementing 


section 3 of the Privacy Bat. of 1974.. escent Register, 


Volume 40, Number. 132, dated. July . op 19753. pe: 28949-28978, 


as supplemented in the Federal Begasterr Volume 40, Number OT 


datea December 4, 1975, Pp- 56741-56743} .. 


SECTION. 1. SCOPE... 


These guidelines establish procedures and Limitations 

‘for matching programs er heey Federal agencies to reduce 

fraud - or unauthorized Payments. in a- Federal programt,. or to 

collect debts owed. to- the- Federal Governnent? establish | 

reporting Beqnivements for matching programs carried out by 

Federal. agencies. for other. purposes; sand establish reporting 

requirements. for- certain disclosures to- non-Federal entities 

for” purposes -of ‘matching. | , a os 
These guidelines aocnoe evens sivel accrue. which are 

not permitted by. law; nor do they: prohibit: activities. expressly 


required to be performed by law. ‘The pugewtieea and Limita- 


tions set forth in these guidelines apply, even when a law 
authorizes or requires a matching program to be carried out, 


to the extent that these procedures and limitations would not 


FrUStr ae rdvaPrdrWehabe LOOP 1723 OME RDPH-0d142R000700040014-9 
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(a) General. The definitions in the Privacy Act 
apply to these guidelines except to the extent that 
they are modified by this section. 
(b) Additional Definitions. 
(1) A "matching program” is a procedure carried 
out by a Federal agency anaes which all ox sub- 
stantially all of the records within a system Of 


records maintained by the agency, or within et 
subsystem of it, are compared by computer with-.” 
(A) all or substantially all of the records 


; within a system of records: ioe subsystem) 


maintained by. BOE HES: agency, ox 


(B) all or Bubstaseiaiie all of any other 


"group of records (or subsystem} that would. 


be covered by the Privacy Act if the records 


were maintained by an agency- 


rd aa ee 


Subsection (B) includes as a "matching program” a program — 
which would otherwise not be covered by these gutaeiines for 
the sole-reason that a Spseua 46 pa nessa ae under the con- 
trol of a matching source (see Section 2(b) (3}) which is not 


an agency, @.g-, a State or local unit of government, ora 


"person" [5 U.S.C. 551(2)]}.- 
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A “matching program” does not include a computer ‘matching 
carried out by an entity which is not an agency; nor does 


it include computer matches which are carried out with records 


obtained within the agency; nor does it include the matching 


of records within a system of records with other Federal 


records which are not from a system of Beneeae. (See, however, 


Section 6 which establishes certain reporting requirements for 


these activities). 


” includes the disclosures which are made 


A "matching program 
to and from a "matching agency” (see Section 2(b} (2Z)) to carry oul 


a matching program or as a result of a matching pragram. 


A "matching program” does not include, for example, checks, 


regardless of the number of such checks, on specific individuals 


in response £0 an application for benefit or as a result. of the 


acquisition of information which raises questions concerning a 
specific individual's eligibility which are Seen contenpo~ 


raneous with that application or scqureteton: 


(2)* A "matching agency” is the agency which is 
carrying out (or which seeks to carry out) a 


matching program. 
(3) A "matching source” is an entity (including 
an agency) which discloses or provides records to 


a matching agency to conduct a matching progran. 


ro 


a 
. 
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REQUIREMENTS FOR MATCHING PROGRAMS--MATCHING AGENCY. 


SECTION 3. 


(a) General. An agency which intends to carry out a 


matching program to reduce fraud or unauthorized payments 
in. a Federal program, or to-collect debts owed to the 


Federal government, should initiate and, conduct the: 


program in accordance with these guidelines. |... - 


(b) A noeening agency should carry out a matching progan— 


payee see ln 


only if there is no other way tao accomplish 


(1) 

the purposes of the matching programs without incurring 
substantially greater costs; ee et a ae 
(2) only in accordance with the Report.on New Systems 
(see Section 3(b) (3)), and only if the matching program 


Will be Fair and equitable to the individuals oye red . a 


q gene. 


will minimize any "chilling" effect upon the exexcise OF 
\ ees 
individual rights; | 


either by (a) establishing a new system “OF 


(3) | 


records for each eee program (a maconiag: 


system"), or (b) by submitting a Repoxt on Wew ‘systems, 


ain accordance with subsection (a} of the Act ree : 


OMB Circular A~108, if an existing ey aban: is amended ; 


and 


(4) 
benefit to the Federal government from the matching 


only if there will be a demonstrable financial 


program, and the benefit significantly outweighs any 


harm to individuals. Benefits may include dollar 


savings (from the reduction of the numbers of 
Approved For Release 2001/11/23 : CIA-RDP81-00142R000700040014-9 


Approved FepRélease 2001/11/23 : CIA-RDP81-00799#R000700040014-9 a6 
unqualified recipients; from deterrence of those 
who would seek benefits for which they are not 

eligible; from expected improvements in deficient: 

' Pederal program operation, etc.) and dollar . 
recoveries from those who have received benefits 
to whieh they were not eneieisas aay costs 
associated with tha watehing program, including 
those of the sacenind, colimetions 1 eveaeions etc. , 
should be deducted from the benefits. | 

{c) In addition to the requirements set forth in oma 

Circular A-108 and in these eevaer Papas tue Report: om 

New Systems for a new or a ctgnged sgsten o£ records 

should include the following: | 
(1) an explanation of why the iguenene aveGuan 
is needed; . 

(2) an explanation of why the matching program can 
reasonably be expected to meet its objectives; 

(3) a description of the other means of achieving 
the objectives of the matching program that the 
matching agency has used or considered; 

(4) a Asseeiseiog oxi the procedures pursuant ta 
which the matching program WLLL be saeice out, 
including a description of the provisions for 
safeguarding information, and for protecting 


personal privacy and. other individual rights; 
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(5) a statement of when the matching program 


will begin, and when it will end; 
(6) a description of the disclosures of records 


which will be made to or eon the systen, including 


the legal justification “on ees ake use involved; 
(7) a description ee a a new information which 


Will be maintained as a- result of ee watching 


program; : : 4 i tae? 


Besar teen OS 


(8) an identification ae each proposed matching 


woe Cores 


source for the program; a eop7 of een routine use 


each source proposes for che matching program; and an 
explanation of every other authority by which the 
matching source furnishes records; and . 


(9) a discussion of those cindiags set forth in 


Sections 3(b) (2) and (4). 


‘a The matching agency should assure before expenses 
are incurred that there is a written agreement among the 
_ participating agencies concerning the expenses of the 


matching program that each Will bear. 


(e) Matching programs should be carried out bY officials 


of the matching agency and not by eenkrsce or grant. 


(f) The number of persons with access to information 
used in the matching program should be limited to the 
minimum number necessary to accomplish its purposes, 


and screening procedures for such employees should be 
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established where appropriate, taking inko account the 
potential £Oe harm or disadvantage that a dis closure 


of the Pieoeaneian might entail. 


(g) The matching program should minimize the number 
and extent of the disclosures of information which 


pertain to identifiable individuals. 


(h) The matching agency should not collect records for 
a matching program from a matching source other than in 


accordance with these guidelines. 


SECTION 4. DISCLOSURES, ACCOUNTING AND DESTRUCTION OF RECORDS. 
(a} Disclosures of records from a matching program shauld 


be made enty with tha BEAOE written apoE Ovet of the matching _ 


epee re ee eee 


ageney official one is vasponsibic o> the system of records, 


(b) Except when specifically required by law, there 
should be no disclosure by the matching agency of records 
obtained from a matching source other than as provided 


in’ 


in this Section. - 


(c) There should be no disclosure of thase records which 
result from a matching program unless the disclosure is | 
necessary to conduct the matching program or to achieve 
its purposes, is limited to the minimum number of persons, 


and is Limited to the minimim amount of information. 


* 
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(d} With regard to disclosures pursuant ta the "xsoutine 
use" provisions of the Act [5 U.S.C. 552a(b) (3}] of those 
records which result from a matching program, the agency 


should: ; oe oe RE SE gD ea a a RON ake UN ett, Mt BBS ns ls eee 
(1) make the routine use as. specific and limited ac 
possible, and, wherever possible, of - a limited Muratiol 


(2) clearly state as a part of the routine) use that 


the records to _ disclosed ‘Include recovas ‘hich ae 


~- ~ wal Meee ee ee 


have resulted from a matching ‘program; ~ 


(3) publish with the Federal ‘Register notice of the 


routine use an explanation of ae pega justification 


for the routine use; 
(4) provide with the Pederal Register notice of the 
routine use an explanation of why the records which | 


may be disclosed pursuant to the routine use cannot 


be disclosed without identifying individuals; 2 


(5) republish in the Federal Register Palen 
consideration of the comments received, ag 


explanation of the comments received gna. ‘the changes mad 
in sufficient detail to pexmit an understanding ‘of 
the basis for the acceptance or rejection o£ each 
comment by the agency; and _ 

(6) ensure that the disclosure is consistent with any cos 
ditions placed upon Ehe disclosure of records by the matc 
ing source at the time the records were disclosec to the- 


matching agency by the matching source. 
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{e) AlL disclosures of those records which result from 


9 


a matching peaevai which are specifically author ized by 

Law but are not made Poeeuene to the routine use provisions 
of he Act, should be made an accordance with the procedures 
in paragraph (d) of this Section whenever possible. For 
example, although the procedures in (d) would not apply to 
each disclosure made in response to a written request by the 
head of a law enforcement agency, ee ee of (da) 


should be followed prior to the initial disclasure to the 


law enforcement agency. 


(f) Whenever: an agency discloses records which ee ee 

a matching program the agency should, as an Sgsvead condi- - 

“tion of the disclosure, set forth the following: 
(1) the use to which the records will be put by the 
entity to whom they are disclosed; 
(2) a stipulation that the eontey. receiving the records 
will disclose them further only rer Tequired by law or 
where (e.g., in the case of a law enforcement: Or admin- 
istrative agency) such disclosure is compatible with the 
purpose for which the records were originally disclosed 


to it; 
(3) the date by which the records transferred will ba 


destroyed, returned to the matching agency or, if it is 
necessary that the records be retained by the entity to 


which a were disclosed, a written explanation of 


that ne cessity. 
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Approveg for Rahase: 2001/11/23 ¢ ClIA-RDPS: guidelines by the matching 
agency does not relieve that agency of compliance with. 
the requirements of the Act, including, for example, 


the requirement to keep an accurate accounting of 
g 


disclosures of records [5 u.S.c. 55Za(c)} J. 


(h) All records which result from a matching pragram 
should. be destroyed within six months, and those records 
which are obtained from a matching source should be 
destroyed or returned to the matching source within six 
months of the beginning of the matching program, except 
for those records which are (1) necessary to the com- 
‘pletion of pending law enforcement activities, or 
administrative activities which are consistent with the 
purposes of the matching program and are authorized by 
law; or (2) otherwise specifically required to be main- 
tained by law. Any extension of tha six-month periad 
should be published, with appropriate explanation, im the 
_Pederal Register. As soon as all of the records have been 
| turned to the matching. source or destroyed, the matching 

| agency should notify the Office of Management and Budget 


in writing... 
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SECTION 5. REQUIREMENTS FOR MATCHING PROGRAMS~-MATCHING 
SOURCES : ig Sig, in Pen tkes ata ee C * oe 


(a) General. The OMB Privacy } Act guidelines im 


ose as 


discussing Conditions of Disclosure, state in parts 

Disclosure, however: is parmissive oe mandatory. 
An Agency is authorized to disclose a record far 
any purpose enumerated below [the exceptions 
to the advance written consent of the individual 
to whom the information pertains] when it deems 
that disclosure to be appropriate and consistent 
with the letter and intent of Bees pau Chase 


guidelines. . 


Nothing in the Privacy Act should be. interpreted 
to authorize or compel disclosures of records, 
not otherwise permitted or required, to anyone 
other than the individual. to whom a record 
pertains pursuant to a request by the individual 
for access to it- - 


Agencies shall not automatically disclose a 
xecord to someone other than the individual 
to whom it pertains simply because such a 
disclosure is permitted by this subsection. 
Agencies shall continue to abide by other , 7 
constraints on their authority to disclose 
information to a third party including, where 
appropriate, the likely effect upon the indi- 

vidual of making that disclosure. Except as 
prescribed in subsection (a) (1), “(individual 
‘access to records) this Act does not require : 
disclosure of a record to anyone other than - 

the individual tdé whom the record pertains. 

(40 Federal Register 28949 at 28953, July 9, 1975.) / 


(b) Specific Requirements: 


(1) aA Federal matching source should review with the 
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matching agency the purposes of and the pro- Me 


cedures for the matching program, and determine 


after such review whether ta eee EE, disclosure 


requested of it by the matching agency. Seo sd en 


eet ae ene "tec, Fae Sen 


2 : sh 
Lohr ata asia ieee ees wom ten sete 


(2) ALL dieelasuras of records Peon a system 


5 i oF ee at Soest S a ae Al ré iat oa cam) i aus is 
o£ paeaeas by ae eoaaeay: matching source to. & mmatehis 


Moet eee, oe See eee 


agency pursuant to- a matching system program 


mee og ty sett a 
eer oon 


os Peta eS “ 
a eee ra en 


should BG made in “accordance with this section Re: 


and the "routine use” provisions o£. =. the Act. 


(3) Unless SRESa EE etry: provided otherwise a 


we at 


by law, no sitcigeure ‘Shoaid be made by a 


matching source for a matching program eaiees 
‘"... the use of such record et oe purpose: 
which is compatible with the purpose . is 

for which [the record] was collected." 


to U.S .C% 552a(a) 7) a | ; xe mieeee 


os Tres, 


(4) Aad eoukine: uses permitting disclosures | 


for matching programs should - mi Gees 


(A) be as , specific oma Pitted GS possible; 


(B) expressly state we the eee use is 


intended toa permit the aiacissues of records 
for a gt Aes ieeaias 
(C} identify the matching program: 


{(D) set forth any conditions which the 
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tir lS were, 


‘matching source has established for the 
- use of the records by the matching agency 


in addition to those set forth in these 


guidelines; and 
(E) be noticed in the Federal Register 
with an explanation or the legal Sere eae 
for the routine use. : 
SECTION 6. AGENCY REPORTS ON OTRER PROGRAMS. = 
(a) Each agency which is carrying eee re en 
to carry out, a matching program for purposes other 
than to reduce fraud or unauthorized payments in 
Federal programs, or to collect debts owed to the 
Federal govermment, should provide notice of that: 
program to the Office of Management and suaece: 
(b) Each agency which intends to disclose wecoees 
from a system of records for purposes of carrying out 
what would be a matching program if the jes Were | 
being carried out by a Federal agency, should provide 
notice to the Office of Management and Budget. 
(c) Each agency which intends to carry out, or is 


‘carrying out, an intra-agency matching program that would 


, 


be subject to these guidelines if it involved the disclosure 


by another ‘agency of records to it, should provide 
Approved For Release, 2001/11/23 : CIA-RDP81-00142R000700040014-9 


Approved For Restehse 2001/11/23 : CIA-RDP81-00142@60700040014-9 


notice to the Office of Management and Budget. 

(d) These notices should include a description of 
the. progean in sufficient detail to permit an. under— 
standing of the purposes and the. procedures Of the | 
program, and shouted set forth iad legal authority 
for the program and the action or Ene agency. The 


notice and BESeET ETT of the matching program should 


eae a 


be submitted at least 60 gaye prior £0 pa ei ee 

of information by the agency or 60 days oes the’ 

initiation of the proposed program, or, as soon 

as practicable. 
SECTION 7. SAFEGUARDS. 


(a) Each matching program (including those agi) 


programs upon which reports were pea Unves Section 5 


of these guidelinas) should incorporate physical, 


ee ee ie technical safequards against ee 
authorized disclosure, alteration or deuce 
Safeguards should be selected Sonnet aes en the 
risk and magnitude Sr toes. harm or disadvantage that 
could result from an iiautnori Sea disclosure, altera— 


tion or destruction of the information within the 


matching system. i 
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(b) The safeguards should, unless the matching source 
of the records agrees otherwise, provide that the 
records are protected at least as stringently as im 
the systems from which the records eee spenquea.* © 
(c) Periodic augiee or. evaluations of the Saeescian 
of these safeguards should be conducted ducing the . 
matching program to assure their sasuunee: i 
(ad) The agency official who is responsible for tia” 
system should certify that based upon the audit ox - 
evaluation, the safeguards are adequate, and eye 
they meet all applicable policies, regulations and 
standards -~- 


SECTION 8. IMPLEMENTATION AND OVERSIGHT 
The Office of Management and Budget will oversee _ 
the implementation of and shall review, interpret 


and advise upon agency proposals and actions under’ 


these guidelines. 


Pe 
rs 
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